Avalon is a marketing hub: you keep your companies and projects here, write posts, and we publish them to the social accounts you connect. This policy explains exactly what we store to do that, who we send it to, and how to get it back or get rid of it. It covers avalonhq.com and the Avalon application.
Avalon is a product of Verge Inc., a corporation registered in the State of California, United States, at 39111 Paseo Padre Pkwy, Suite 202, Fremont, CA 94538. Verge Inc. is the data controller for the information described here. For anything in this policy — access, correction, deletion, or a complaint — write to [email protected], or to that address, and a person will answer.
When you connect a social account to a project we store its platform id, display name, profile picture URL, the granted scopes, and an access token (plus a refresh token where the platform issues one). Tokens are encrypted at rest and are never shown in the browser or sent to your device. We use them only to publish what you schedule and to read the settings a platform requires us to display before posting.
We do not read your followers, direct messages, comments, or posts you made outside Avalon.
avalon_session) that keeps you signed
in. It holds a random token, not your identity, and lasts 30 days. It is strictly
necessary — Avalon cannot work without it.avalon_project) remembering which
project you were last working in.We do not use advertising cookies, third-party analytics or tracking pixels.
| Purpose | Basis (UK/EU GDPR, where it applies) |
|---|---|
| Running your account and publishing your posts | Performance of a contract |
| Sending service email (activation, security notices) | Performance of a contract |
| Keeping the service secure and preventing abuse | Legitimate interests |
| Improving reliability from error logs | Legitimate interests |
| Marketing email from you to your contacts | Your responsibility as sender — see §8 |
When you use "Write with AI" or generate a poster, we send the relevant text — your brief,
the post content, and the project context you wrote (company, industry, project details) —
to our self-hosted AI service at ai.somezing.com. Generated images are stored
with your other media. We do not use your content to train models, and it is not shared
with third-party AI providers.
We record how long each generation took, so the progress bar can be honest. That timing carries no content.
We do not sell your data, ever. We share only what a given feature requires:
| Who | What | Why |
|---|---|---|
| LinkedIn, X, Instagram, TikTok | The post you scheduled and its media | To publish it, when you tell us to |
| Amazon Web Services (S3, CloudFront) | Uploaded and generated media | Storage and delivery |
| SomezingAI | Text and context you submit to AI features | Drafting and image generation |
| SendGrid | Recipient address and message | Sending email you compose |
| Twilio | Recipient number and message | Sending SMS, WhatsApp and calls you compose |
| OpenStreetMap or Google Places | The search terms you type | Finding business contacts |
We may also disclose information where the law requires it, or to protect the rights and safety of our users.
Verge Inc. is a US company and data is held in Amazon Web Services in the United States. If you are in the UK or EEA, that is a transfer outside your region; it relies on the provider's Standard Contractual Clauses.
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it. Email [email protected] and we will respond within one month. If you are in the UK or EEA you may also complain to your local data protection authority; California residents have rights under the CCPA/CPRA, including to know what we hold and to have it deleted, and we do not sell or share personal information.
Practical routes: archive a company or project from inside the app, disconnect a social account under Edit project → Social Media, and see Delete your data for account deletion and platform-initiated erasure.
When you import contacts or send campaigns, you are the data controller for those people and Avalon is your processor. You are responsible for having a lawful basis to hold and message them, for honouring unsubscribe requests, and for complying with GDPR, CAN-SPAM, PECR and any other rules that apply to you. We process them only to deliver what you ask.
Passwords are bcrypt-hashed. Social tokens are encrypted at rest with Fernet. Sessions are stored server-side, keyed by a hash of the session token, so a stolen database row cannot be replayed as a login. Traffic to avalonhq.com is served over HTTPS. No system is perfectly secure, and we will tell you promptly if a breach affects your data.
Avalon is a business tool and is not intended for anyone under 16. We do not knowingly collect their data; tell us if you believe we have and we will remove it.
If we change this policy we will update the date above, and tell you by email when the change is significant.
This policy describes how Avalon actually works today. It is not legal advice; if you are relying on it for compliance in your own jurisdiction, have your counsel review it.